feat(v30-T1): C4 fleet inventory, contract tests CI, CycloneDX SBOM gen, lock hash check, SSOT drift cron - #121
Conversation
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
|
CodeAnt AI is reviewing your PR. |
Thanks for using CodeAnt! 🎉We're free for open-source projects. if you're enjoying it, help us grow by sharing. Share on X · |
|
Warning Review limit reached
Next review available in: 19 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (5)
Note
|
|
CodeAnt AI finished reviewing your PR. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d3339d2ad7
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| with: | ||
| node-version: ${{ env.NODE_VERSION }} | ||
| cache: npm | ||
| - run: npm ci |
There was a problem hiding this comment.
Run contract tests from an actual npm project
In the inspected tree there is no root package.json or package-lock.json (the manifests are only in nested packages such as open-sse/, electron/, and @omniroute/*), but this workflow runs npm ci from the repository root on every matching PR/manual run. That makes the new Contract Tests check fail before it can either run or intentionally skip tests/contract, so source changes get a red CI job unrelated to contract test results.
Useful? React with 👍 / 👎.
| - name: Check docs sync (source vs generated) | ||
| run: npm run check:docs-sync 2>&1 || echo "Drift detected — run 'npm run docs:sync' locally." | ||
| - name: Check route validation drift | ||
| run: npm run check:route-validation:t06 2>&1 || echo "Route validation drift detected." |
There was a problem hiding this comment.
Fail the drift scan when checks detect drift
For scheduled/manual SSOT scans, both validation commands are followed by || echo, so any non-zero exit from docs-sync or route-validation is converted into a successful step and the workflow stays green even when drift is detected. Since the summary says this is the weekly drift scan, this produces false-negative monitoring; use a failing exit status or an explicit issue/artifact path if the scan should report drift without blocking.
Useful? React with 👍 / 👎.
…en, lock hash check, SSOT drift cron Track T1 of the v30 71-pillar P2-lift plan. Five deliverables: - (a) .github/inventory/fleet.json — C4 component+container model for OmniRoute (6 containers, 5 relationships, system context) - (b) .github/workflows/contract_tests.yaml — CI workflow for boundary contract tests (triggered on PR paths: src/ open-sse/ tests/contract/) - (c) .github/workflows/sbom-gen.yaml — CycloneDX SBOM generation CI (on push to main touching package.json, weekly Monday @06:00 UTC, manual) - (d) .github/workflows/cargo-lock-hash.yaml — Weekly lock file determinism check (SHA256 hash verification, npm ci --dry-run integrity test) - (e) .github/workflows/ssot-drift-cron.yaml — Weekly SSOT drift scan (docs-sync, route-validation provider-catalog drift checks) Refs: Pillars L2, L27, L29, L30, L65
d3339d2 to
9b54f8f
Compare
L17 Latency Budget ReportChecked against: budgets/rest-endpoints.yaml. |
|
| cache: npm | ||
| - run: npm ci | ||
| - name: Check docs sync (source vs generated) | ||
| run: npm run check:docs-sync 2>&1 || echo "Drift detected — run 'npm run docs:sync' locally." |
There was a problem hiding this comment.
[WARNING]: || echo masks non-zero exit from docs-sync check
npm run check:docs-sync is followed by || echo, converting any non-zero exit into a successful step. The workflow stays green even when drift is detected because the failure is swallowed before it can fail the job.
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
| - name: Verify deterministic install | ||
| run: | | ||
| BEFORE=$(sha256sum package-lock.json | cut -d' ' -f1) | ||
| npm ci --dry-run 2>&1 | head -5 || true |
There was a problem hiding this comment.
[WARNING]: || true masks npm ci --dry-run failure
Without a root package.json, npm ci --dry-run fails immediately. The || true swallows that failure, so the BEFORE/AFTER hash comparison always passes and the workflow reports a false-positive "deterministic" result instead of surfacing the missing manifest.
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
| @@ -0,0 +1,66 @@ | |||
| { | |||
| "$schema": "https://raw.githubusercontent.com/kooshapari/phenotype-registry/main/schemas/c4-fleet.schema.json", | |||
There was a problem hiding this comment.
[WARNING]: $schema references a personal fork instead of the canonical registry
The schema URL points to kooshapari/phenotype-registry (a personal fork) rather than the canonical phenotype-registry organization. Schema validation breaks if the fork is renamed, deleted, or made private.
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
| "systems": { | ||
| "omniroute": { | ||
| "name": "OmniRoute", | ||
| "description": "Unified AI proxy/router — route any LLM through one endpoint. 232 providers, 15 routing strategies, 87 MCP tools, 42 i18n locales.", |
There was a problem hiding this comment.
[SUGGESTION]: Stale provider count in inventory metadata
The description states "232 providers" but the repository's own AGENTS.md documents "231 providers" (verified at AGENTS.md:11). Inventory metadata like this drifts over time without an automated generation step.
Reply with @kilocode-bot fix it to have Kilo Code address this issue.
Code Review SummaryStatus: 4 Issues Found | Recommendation: Address before merge Overview
Issue Details (click to expand)WARNING
SUGGESTION
Files Reviewed (5 files)
Fix these issues in Kilo Cloud Reviewed by step-3.7-flash-20260528 · Input: 360.2K · Output: 19.5K · Cached: 1.8M |



User description
Track T1 — Docs + contract + SBOM + lock + cron
Part of the v30 71-pillar P2-lift sprint plan (plans/2026-06-27-v30-71-pillar-p2-lift.md).
Deliverables
.github/inventory/fleet.json.github/workflows/contract_tests.yamlsrc/open-sse/tests/contract/.github/workflows/sbom-gen.yaml.github/workflows/cargo-lock-hash.yamlnpm ci --dry-run).github/workflows/ssot-drift-cron.yamlChange summary
5 new files, 237 lines added. Follows OmniRoute CI conventions (concurrency groups, SHA-pinned action versions, ubuntu-24.04, Node 24).
Verification
.github/workflows/(ci.yml, sbom.yml, security-scan.yml)workflow_dispatch:for manual triggering.github/inventory/fleet.jsonuses the standard C4 schemaRefs: Pillars L2, L27, L29, L30, L65
CodeAnt-AI Description
Add scheduled CI checks and update project status docs
What Changed
package-lock.jsonstays unchanged during install and reports the file hash in the run summaryImpact
✅ Earlier detection of broken lock-file changes✅ Downloadable SBOMs for release and audit checks✅ Fewer regressions in contract-boundary changes💡 Usage Guide
Checking Your Pull Request
Every time you make a pull request, our system automatically looks through it. We check for security issues, mistakes in how you're setting up your infrastructure, and common code problems. We do this to make sure your changes are solid and won't cause any trouble later.
Talking to CodeAnt AI
Got a question or need a hand with something in your pull request? You can easily get in touch with CodeAnt AI right here. Just type the following in a comment on your pull request, and replace "Your question here" with whatever you want to ask:
This lets you have a chat with CodeAnt AI about your pull request, making it easier to understand and improve your code.
Example
Preserve Org Learnings with CodeAnt
You can record team preferences so CodeAnt AI applies them in future reviews. Reply directly to the specific CodeAnt AI suggestion (in the same thread) and replace "Your feedback here" with your input:
This helps CodeAnt AI learn and adapt to your team's coding style and standards.
Example
Retrigger review
Ask CodeAnt AI to review the PR again, by typing:
Check Your Repository Health
To analyze the health of your code repository, visit our dashboard at https://app.codeant.ai. This tool helps you identify potential issues and areas for improvement in your codebase, ensuring your repository maintains high standards of code health.